5
CVSSv2

CVE-2013-7100

Published: 19/12/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the unpacksms16 function in apps/app_sms.c in Asterisk Open Source 1.8.x prior to 1.8.24.1, 10.x prior to 10.12.4, and 11.x prior to 11.6.1; Asterisk with Digiumphones 10.x-digiumphones prior to 10.12.4-digiumphones; and Certified Asterisk 1.8.x prior to 1.8.15-cert4 and 11.x prior to 11.2-cert3 allows remote malicious users to cause a denial of service (daemon crash) via a 16-bit SMS message with an odd number of bytes, which triggers an infinite loop.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk digiumphones 10.11.0

digium asterisk digiumphones 10.12.0

digium asterisk 10.12.0

digium asterisk 10.10.0

digium certified asterisk 11.2.0

digium certified asterisk 1.8.15

digium asterisk 11.4.0

digium asterisk 11.0.0

digium asterisk 11.1.1

digium asterisk 11.1.2

digium asterisk 1.8.20.0

digium asterisk 1.8.21.0

digium asterisk 1.8.17.0

digium asterisk 1.8.18.0

digium asterisk digiumphones 10.0.0

digium asterisk digiumphones 10.12.1

digium asterisk digiumphones 10.12.2

digium asterisk 10.11.0

digium asterisk 11.2.0

digium asterisk 11.3.0

digium asterisk 11.5.0

digium asterisk 11.5.1

digium asterisk 11.0.2

digium asterisk 11.1.0

digium asterisk 1.8.23.0

digium asterisk 1.8.22.0

digium asterisk 1.8.19.0

digium asterisk 11.0.1

digium asterisk 1.8.18.1

digium asterisk 10.12.2

digium asterisk 10.12.1

digium asterisk 1.8.19.1

Vendor Advisories

Jan Juergens discovered a buffer overflow in the parser for SMS messages in Asterisk An additional change was backported, which is fully described in downloadsasteriskorg/pub/security/AST-2013-007html With the fix for AST-2013-007, a new configuration option was added in order to allow the system adminitrator to disable the expansion of ...